Impact
This vulnerability allows an attacker to execute arbitrary code on the SailPoint IdentityIQ server without authentication. It stems from improper validation of data submitted through the web service API. The lack of input validation enables malicious content to be processed, leading to full server compromise. The weakness manifests as a classic input validation flaw (CWE‑20).
Affected Systems
All versions of SailPoint IdentityIQ are affected. The vulnerability is present in every release of the product as the input validation issue has not been addressed yet. No specific version boundary is given, so any deployment of IdentityIQ is at risk.
Risk and Exploitability
The CVSS score of 9.6 classifies this issue as critical. EPSS information is not available, but the fact that the vulnerability is remote, unauthenticated, and powerful code execution suggests a high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but that does not reduce its severity or potential impact. An attacker can exploit the flaw by sending crafted API requests to the IdentityIQ server over the network; no local privilege or user interaction is required. This creates a very high risk for organizations running unpatched systems.
OpenCVE Enrichment